Server-Side Request Forgery Vulnerability in Amazon AWS Systems Manager Agent
CVE-2026-89049

8.5HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
10 September 2026

What is CVE-2026-89049?

Amazon AWS Systems Manager Agent is vulnerable to a server-side request forgery issue due to improper validation of address representations in its port forwarding functionality. This vulnerability could allow an authenticated remote user to bypass the destination denylist and connect to link-local endpoints. By exploiting this flaw, attackers might gain unauthorized access to temporary IAM role credentials of a managed instance, enabling them to execute actions using the role's permissions from outside the instance. Users are advised to upgrade to version 3.3.4851.0 or later to mitigate this risk.

Affected Version(s)

Amazon SSM Agent 0 < 3.3.4851.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.